1. Introduction
This Privacy Policy explains how Turbsol Management, LLC ("we", "us", or "our"), the company that makes and operates the AvTools platform, formerly Longeron and originally JASSCO, collects, uses, and shares information across the AvTools platform and its web and mobile applications and modules, including AvPics (web and the AvPics iOS app), the Filing Assistant, QuoteDeck, the Finance module, Station, the Trace paperwork packager, the Reference Library, document signing and e-signature, the AI assistant, and the Arcade activity layer (collectively, the "Services"). It should be read together with our Terms of Service. For a technical description of how we isolate and protect customer data (including for AI features) see our Security page. If you are in the European Economic Area, the United Kingdom, or Switzerland, our GDPR Compliance Statement describes how this policy maps to the GDPR.
Company Information
Service Name: AvTools (AvPics, Filing Assistant, QuoteDeck, Finance, Station, Trace, and related modules)
Data Controller: Turbsol Management, LLC (AvTools is its product brand)
Email: legal@avtools.aero
Phone: +1-980-414-8848
Website: https://www.avtools.aero
2. Scope
This policy applies to information collected through the Services, whether accessed via the web application or the mobile (iOS) app. Most data is processed on behalf of the customer organization that holds the account; in that context the organization is the controller of its operational data and AvTools acts as its processor.
3. Information We Collect
3.1 Account & Authentication
- Name, email address, and (for password sign-in) a hashed password; or a single sign-on identity such as Microsoft Entra where configured
- Company/organization name and your role/permissions (e.g., admin, member, inspector)
- Profile avatar and basic activity counters (last active, session counts), and user invitations (invitee email, assigned role)
3.2 Aviation Operational Content
- QC photos & images: part, data-plate, serial-number, defect, packaging, certificate, and shipping-label photos, including annotated images
- Capture metadata: timestamps, captions, severity ratings, photo type, inspector name, and optional GPS location (only if you enable location tagging)
- Part & work data: part/serial numbers, barcode values, work-order/PO/SO/RO/RMA/invoice IDs, condition codes, inspection notes
- Generated documents: assembled photo and inspection-report PDFs, and outbound trace packages assembled from your records and ERP attachments
- Scanned documents: PDFs your organization routes through document scanning (e.g., a scanner hot folder), which we attach to the matching ERP record
- Quotes & RFQs (QuoteDeck): customer/contact names and emails, quote numbers, prices, line totals; and inbound RFQ emails (sender/recipient, subject, and full message body) when you use email-to-quote
3.3 Integration Credentials
When you connect a third-party system, we store the OAuth tokens, API keys, and connection settings needed to operate the integration (e.g., Salesforce/AvSight, QuickBooks, Smart145, SkySelect, PrintNode). These are held server-side with restricted access and, on the iOS app, in the device Keychain.
3.4 Billing & Subscription
- Web/organization plans: Stripe customer and subscription identifiers, plan/seat selections, billing email and address, invoice status, and subscription/invoice events. We never see or store your card details. Stripe processes payments.
- iOS in-app purchases (not currently offered): The AvPics app does not currently offer in-app purchases. If we add them, Apple would process the payment and we would process transaction IDs, receipts, product/plan, subscription status, trial/period and auto-renewal information, and receipt-validation results. We would update this policy before offering that billing option.
- Contracts: plan/term details, signer name, signature status, and the signed-document reference.
3.5 Device & Usage Data
- Device id/name/model/type, OS and app version, platform
- IP address, user agent, login/logout method, session start/end and duration, and a hashed session token
- Basic diagnostics, sync logs, and feature-usage patterns
3.6 AI Assistant Content & AI Access Logs
If you use the in-app AI assistant, we store your chat sessions and messages, and the inputs you submit are processed by our AI provider as described in Section 4.3 and Section 5.2. We also keep an append-only AI access log designed to record what AI surfaces read: the organization, the acting user (or connector identity), which surface and tool were used, and summary details of the request, so that AI access to your data can be reviewed. Logging is best-effort: a logging failure does not block operational work. The same best-effort logging applies when your organization connects an external AI client to our hosted read-only data endpoint; we attempt to record each tool call with the authenticated caller's identity.
3.7 Signature & Certification Records
- E-signature (counter-party documents): signer name and email, the document field values we prefill, signature status and timestamps, the signed document, and a send/completion audit trail. Processing runs on our self-hosted e-signature service (DocuSeal).
- Sign & Seal (internal certification): for documents our staff or your organization's named signers certify: the signer's identity (name, role, and work email, sourced from Microsoft Entra where the company is configured to use it, or from the signer's AvTools account otherwise), the attestation text, signing timestamps and authentication method, cryptographic document seals and trusted timestamps, and an append-only audit log.
- Public verification: sealed documents print a verification link. Anyone who has the document (and therefore the link) can view that certificate's verification page, which displays the issuing company, the signer's name, role, stamp, and work email, and the signing/authentication timestamps. Treat a sealed document itself as carrying this information.
3.8 Workplace Activity & Arcade
If your organization enables the Arcade (an optional activity layer), we derive activity events from work already recorded in the Services (for example batches pushed, quotes sent, filings completed) and compute per-user scores, ranks, quest and trophy progress, and company objectives. These are visible to your teammates and administrators on your company's leaderboard and feeds (scoped to your organization only), under your name or an optional callsign you choose. A weekly recap email may be sent to participants and administrators; each user can opt out in their Arcade settings ("Email me a weekly recap").
3.9 Sales, Support & Other
- Demo-request leads (name, email, phone, company, size, role, message)
- Support communications, attachments, and bug reports
- Cargo-insurance certificates (certificate number, coverage, premium, freight reference) when you purchase coverage
- Audit/compliance records (e.g., quote-write audit trail, filing-checklist status and notes, document-print events)
- Email delivery metadata: our email provider notifies us of delivery lifecycle events (delivered, bounced, opened) for emails the platform sends, which we use to track whether operational emails (e.g., payment reminders) actually arrived
3.10 Cookies & Similar Technologies
We use cookies and browser storage only to run the Services, not to advertise or track you across the web:
- Strictly necessary cookies: set when you sign in, to keep your authenticated session working securely (our authentication provider, Supabase). Blocking these prevents sign-in.
- Browser storage (localStorage/sessionStorage): interface preferences and, for our error monitoring (Sentry, Section 5.3), short-lived identifiers used to group diagnostics from the same session.
- What we do not use: no advertising cookies, no cross-site tracking, no third-party ad networks, and no analytics cookies on our public marketing pages. We do not sell or share cookie data.
You can clear or block cookies in your browser settings; essential sign-in cookies will be set again the next time you log in.
What We Do NOT Collect
The Services are not designed to collect sensitive personal information (such as government ID numbers, financial account numbers, or biometric identifiers beyond device-level Face ID/Touch ID) unless your organization intentionally includes such information in uploaded content. We recommend avoiding upload of sensitive personal information unless strictly necessary for your aviation compliance processes.
Important: We never see or store your credit/debit card or payment-method details. Card processing is handled by Stripe for current web/organization billing. Apple would process any future iOS in-app purchases, which are not currently offered.
4. How We Use Information
4.1 Provide & Operate the Services
- Capture, organize, and store QC photos and batches; scan barcodes; generate PDFs and inspection reports
- Authenticate users and enforce role-based access; manage seats and entitlements
- Run QuoteDeck, Filing Assistant, and Finance workflows, and sync with your connected systems
- Maintain security, prevent fraud and abuse, troubleshoot, and improve reliability and performance
- Provide customer support
4.2 Subscription & Billing
To verify active subscriptions, grant feature access by tier, process renewals/cancellations, handle billing retries, and meet financial-compliance obligations.
4.3 AI-Assisted Features
When you use the AI assistant or AI-assisted summaries, the relevant inputs and context are sent to our AI provider to generate a response. Our AI providers contractually do not use your data to train their foundation models, and we do not use Customer Data to train AI models (see Section 6.3). AI output may be inaccurate; you are responsible for verifying it before relying on it.
6. Content Ownership and Intellectual Property
6.1 Your Data Belongs to You
All photos, documents, inspection records, quotes, part data, and other content you upload or create using the Services ("Customer Data") is and remains your property (or your organization's property). Turbsol Management, LLC does not acquire any ownership rights to Customer Data.
6.2 Limited Processing License
We process Customer Data solely to provide the Services: storing, backing up, transmitting, and displaying it as needed to operate them (including via the sub-processors above). We do not use Customer Data for any other purpose.
6.3 No Secondary Use
We will not:
- Use Customer Data for advertising
- Sell, license, or share Customer Data with third parties for their own purposes
- Use Customer Data to train artificial-intelligence or machine-learning foundation models
- Mine Customer Data for insights beyond what is needed to provide the Services or to produce the aggregated statistics described below
We may produce aggregated, de-identified data from use of the Services and use it to operate, secure, support, and improve them and to publish industry statistics and benchmarks. This data combines information across multiple customers and is stripped of anything that identifies you, your users, your counterparties, or an individual transaction. Three limits apply and we hold ourselves to all of them: we will not publish a figure derived from so few customers or records that one company's numbers could be worked back out of it; we will not disclose Customer Data itself this way; and we will not name you as the source of a statistic without your permission. Aggregated data is never used to train AI or machine-learning foundation models. That prohibition applies to derived data exactly as it applies to Customer Data.
6.4 Data Portability
You may request a full export of your Customer Data at any time. We will provide it in standard, machine-readable formats (CSV, JSON, or PDF as appropriate) within 30 days of request.
6.5 Service Discontinuation
If Turbsol Management, LLC discontinues the Services:
- We will provide at least 90 days written notice
- You will have full access to export your Customer Data during the notice period
- Customer Data will not be treated as a business asset in any sale, merger, or bankruptcy proceeding
- We will permanently delete Customer Data after confirming successful export or at the end of the notice period, whichever comes first
6.6 Enterprise Content Protection
For enterprise and organizational customers, your proprietary business data, trade secrets, processes, and methodologies stored in the Services are protected under this policy and our Terms of Service. AvTools's access to such data is strictly limited to service delivery and authorized support activities.
7. Data Retention
Active Accounts: We retain information as long as your account is active and for legitimate business purposes.
Account Deletion: When you delete your account:
- Data is marked for deletion within 30 days
- Backups may persist for up to 90 days
- Some data may be retained longer for aviation compliance and legal requirements (FAA/EASA record-keeping mandates)
7.1 Specific Retention Periods
- Subscription & transaction records: duration of subscription plus up to 7 years (financial compliance)
- Subscription events: up to 3 years (dispute resolution)
- Failed iOS receipt validations, if in-app purchases are offered: until resolved or 90 days
- Aviation inspection records: per FAA/EASA requirements (typically 2–7 years depending on record type)
Organization Policies: Your organization may have its own retention policies for aviation inspection records that supersede general data-retention practices.
8. Security
A fuller, technical account of these controls (including how AI features are constrained) is published on our Security page.
8.1 Data Encryption & Storage
- Data encrypted in transit (TLS)
- Passwords hashed (Supabase Auth / bcrypt)
- Database and storage encryption at rest
- QC photos and generated documents are held in private storage (not on public URLs) and are served through an authorizing endpoint that checks your organization membership and issues short-lived, expiring links
- Integration credentials (OAuth tokens, API keys) are readable only by server-side service code: database policy denies ordinary user sessions any access to them; on iOS they live in the device Keychain
8.2 Access Controls
- Per-organization row-level security on operational tables and role-based access control (RBAC)
- Single sign-on and multi-factor authentication available (enforced at your identity provider)
- Face ID / Touch ID support on mobile
8.3 Auditability
- AI reads of customer data are submitted to a best-effort, append-only access log attributed to the acting user or connector (Section 3.6)
- Signing and certification events are recorded in an append-only audit log (Section 3.7)
- ERP pushes, document prints, and quote writes carry their own audit trails
8.4 Infrastructure
- Supabase/AWS and Vercel security infrastructure
- Regular updates, vulnerability scanning, and monitoring
Note: No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we implement industry-standard practices.
9. Your Choices & Rights
Depending on your location and applicable laws, you may have rights to:
- Access a copy of your data
- Correct inaccurate information
- Delete your account and data (subject to aviation record-keeping requirements)
- Export your data in a portable format
- Object to certain processing
EEA users have additional rights under the GDPR (rectification, erasure, portability, and to lodge a complaint with a supervisory authority). Our GDPR Compliance Statement describes them in full, along with our lawful bases and how we handle international transfers. California residents have rights under the CCPA/CPRA to know, delete, correct, and to non-discrimination for exercising rights. International transfers rely on Standard Contractual Clauses or other appropriate safeguards.
How to Exercise Your Rights
- Organization-managed accounts: contact your administrator first.
- Direct requests: contact us at legal@avtools.aero.
- Response time: within 30 days.
10. Children's Privacy
The Services are professional business applications intended for aviation-industry professionals. They are not intended for use by children under 18, and we do not knowingly collect personal information from children.
11. International Transfers
If you use the Services from outside the United States, your information may be transferred to and processed in the United States (where our primary infrastructure runs) and other jurisdictions where our sub-processors operate. Those jurisdictions may have different data-protection laws; we use Standard Contractual Clauses and other appropriate safeguards for such transfers. Our GDPR Compliance Statement describes the transfer mechanisms in more detail.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be posted on this page with an updated effective date.
13. Contact Us
For questions about this Privacy Policy, or to request access, correction, or deletion, contact us at:
Privacy Officer: AvTools Legal Team
Email: legal@avtools.aero
Phone: +1-980-414-8848
Response Time: Within 30 days